<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.lkspa-wimse-verifiable-geo-fence" target="https://datatracker.ietf.org/doc/html/draft-lkspa-wimse-verifiable-geo-fence-00">
   <front>
      <title>Modernizing Workload Security: Verifiable Geofencing, Proof-of-Possession, and Protocol-Aware Residency Enforcement</title>
      <author initials="R." surname="Krishnan" fullname="Ramki Krishnan">
         <organization>Intel</organization>
      </author>
      <author initials="N." surname="Smith" fullname="Ned Smith">
         <organization>Intel</organization>
      </author>
      <author initials="D." surname="Lopez" fullname="Diego Lopez">
         <organization>Telefonica</organization>
      </author>
      <author initials="A." surname="Prasad" fullname="A Prasad">
         <organization>Oracle</organization>
      </author>
      <author initials="S." surname="Addepalli" fullname="Srinivasa Addepalli">
         <organization>Aryaka</organization>
      </author>
      <date month="June" day="23" year="2025" />
      <abstract>
	 <t>   Modern cloud and distributed environments face significant risks from
   stolen bearer tokens, protocol replay, and trust gaps in transit.
   This document presents a framework for modernizing workload security
   through cryptographically verifiable geofencing, proof-of-possession,
   and protocol-aware residency enforcement.  By binding workload
   identity to both geographic and host attributes, and supplementing
   bearer tokens with verifiable, location- and host-bound claims, the
   framework addresses the challenges of bearer token theft, proof-of-
   possession, IPSEC, and trust-in-transit.  Leveraging trusted
   hardware, attestation protocols, and geolocation services, this
   approach ensures that only authorized workloads in approved locations
   and environments can access sensitive data or services, even in the
   presence of advanced threats.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-lkspa-wimse-verifiable-geo-fence-00" />
   
</reference>
